CVE-2025-12490
largeAuthenticated Path Traversal RCE in Netgate pfSense CE Suricata Package
CVE-2025-12490 is a path traversal flaw (CWE-22) in the Suricata package for Netgate pfSense CE, caused by insufficient validation of a user-supplied path before it is used in file operations. A remote attacker who holds valid low-privilege credentials on the pfSense web interface can submit a crafted path to create arbitrary files on the firewall. Because files are written in the context of root, this can be leveraged for full remote code execution with highest impact on confidentiality, integrity and availability (CVSS 3.0 score 8.8). Only pfSense CE deployments that have the Suricata package installed are affected, and exploitation requires authentication. No public proof-of-concept is known, the flaw is not in CISA's KEV catalog, and it is not yet known to be exploited in the wild, although a high EPSS score (20.1%, 97th percentile) indicates a meaningful chance of exploitation within 30 days.
What to do: Apply the patched Suricata package update via the pfSense Package Manager as soon as Netgate publishes it, and check the ZDI advisory (ZDI-CAN-28085) for the fixed version. Until then, restrict access to the pfSense web interface to trusted management networks and review local accounts, since exploitation requires valid credentials. Check affected firewalls for unexpected root-owned files or new persistence artifacts as a precaution.
| Netgate pfSense CE (Suricata package) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Netgate pfSense CE Suricata Path Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to create arbitrary files on affected installations of Netgate pfSense. Authentication is required to exploit this vulnerability. The specific flaw exists within the Suricata package. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to create files in the context of root. Was ZDI-CAN-28085.
- Weakness
- CWE-22
- Vector
- CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.